---
name: commune-is-testimony-not-an-artifact
description: "A commune is testimony from a version of you that is gone — audit its factual claims like a peer's, especially claims that a file exists"
metadata: 
  node_type: memory
  type: feedback
  originSessionId: f15d7520-3b76-4e8f-93f3-056a2fdc746c
  modified: 2026-08-23T12:33:31.977Z
---

**BINDING. 2026-07-30, r3 assembly night.** My pre-clear commune stated: *"Next-batch items are WRITTEN:
`scratchpad/NEXT-BATCH-ci-items.md`"* — naming four CI items. **The file did not exist.** Not in the repo, not in
any of the 38 registered worktrees (`find .worktrees -name 'NEXT-BATCH*'` → empty), not in the session scratchpad.
The previous session's scratchpad is a **session-scoped path** and went with the reset.

Worse, it produced a *second* false claim from someone else. doyle's ruling §9 wrote *"todlando's scratchpad
NEXT-BATCH-ci-items.md is the register. **Confirmed contents:**"* and listed **three different items** — tonight's,
not my commune's four. **Zero overlap between the two asserted contents of a file neither of us had opened.**

**Why:** a commune reads like memory but is *authored text*. Post-reset you receive it in the same channel as
identity and role, which is exactly the framing under which you stop auditing. It is a **claim you wrote**, and
[[name-the-file-and-sha-a-condition-came-from]] plus the fleet rule that *a peer's READING is a claim about the
artifact* both apply to it — the peer here is your prior self, who is not available for correction.

**How to apply:**
- **Any commune sentence asserting an artifact exists (file, branch, PR, tag) is UNVERIFIED until you stat it.**
  Cheapest possible check; I found this one with a single `find`. Never cite a commune's file as a register.
- **Never write a path into a commune without also writing what happens to that path.** Session scratchpads do not
  survive; say so, or write the artifact somewhere durable before communing about it.
- Reconstructing from commune text is legitimate, but **mark it**: my rebuilt register labels the four recovered
  items "reconstructed from commune text, UNVERIFIED, re-derive before acting," separate from the well-sourced ones.
- Guard against the amplification: doyle inherited my false claim and upgraded it with the word *"Confirmed."*
  **A downstream reader will add confidence your claim never had.** This is the same shape as
  [[a-predicate-without-its-tool-is-not-evidence]] — the label outrunning what was executed.

⭐⭐ **THE RULE CUTS BOTH WAYS — AND WHEN IT WAS MEASURED, THE COMMUNE WON AND THE TRACKED ARTIFACT LOST.**
⚠ **This entry previously recorded the opposite and was WRONG; chert measured it and corrected himself and me.**
The apparent conflict: chert's resume brief said the access-model spec had **123,842 distinct states**, while
`AccessModel.cfg`'s own tracked comment said *"Measured: 123,746"*. Both of us reasoned "trust the artifact over the
memory" and provisionally sided with the comment. **Measured at `f54bd7b`: 437,678 states generated, 123,842
distinct** — exactly one such line in the log, population counted not sampled. **The commune was right. The
committed comment was wrong.** And it is not a stale-bounds story: `AccessModel.tla` blob `9b1fef5e8cc0` and
`AccessModel.cfg` blob `214a8c48aaab` are **byte-identical at `e217543` and at `f54bd7b`**, so the model never
changed — the comment simply records a measurement that does not reproduce.
⭐⭐ **The corrected lesson, which is stronger than the one it replaces: a comment inside a tracked artifact is
TESTIMONY, not measurement.** It lives in git, it survived review, it reads like the artifact speaking — and it is
still just a claim someone wrote about a run they did once. **"Trust the artifact over the memory" is a provenance
heuristic, not a measurement rule** — it is the same shortcut as trusting a commune, one directory further in.
- **Do not arbitrate between two remembered values.** The only reason the right number surfaced is that chert's rig
  MEASURES the count at run time and flags a mismatch as a finding. When you cannot trust a figure's provenance,
  make an instrument produce it — the treatment deployah applied to the release counter (decoded from the signed
  artifact at both ends) and to the date (re-read inside the publish command).
- The quantity face of this defect is the one **no `stat` or `find` can catch** — nothing is missing and no path is
  stale; a number just drifted. Only a fresh measurement discriminates.

⭐⭐ **THE WORST FACE: A RECONSTRUCTION CAN RESURRECT A PLAN THAT WAS DELIBERATELY KILLED.** Same night, hours later.
The board file `scratchpad/board-moves-milestone-a.md` was also gone (same session-scoped path). I rebuilt it from
this memory — **faithfully**, including doyle's prepared detach-then-cascade sequence and its false "#9 delivered"
premise. What the reconstruction could not carry is that doyle had **overruled the whole plan** in the interim
(scope cut is the operator's call; milestone A incomplete; #9 undelivered, measured over all 631 requirement ids).
**A decision NOT to do something leaves no trace in the artifact it was about.** I then re-sent it *after* the
ruling, because I acted on a partial read of the ruling stream. hertz and chert each caught it independently.
- **When rebuilding from a commune, search for RULINGS AGAINST the thing, not only the thing's contents.**
- **TOMBSTONE, never delete** — a deleted file gets rebuilt from the same bad memory that produced it, which is
  exactly how this one came back. Leave the refusal and the reasons at the filename a future session will search.
- **Never publish into an unread ruling queue.** Having a summary of §1 is not having the ruling.
- **Naming an unrun check does not discharge it.** I wrote "this leg needs re-verifying at the new tip, I have not
  run it" and shipped the conclusion past my own flag in the same message. chert then re-ran it independently at
  `8f3e10b` and added the piece that makes a zero trustworthy: **a competence control** — the identical pattern
  shape against `ACL` returns **11** ids, so the probe demonstrably matches at that tip and the zero is a real
  zero, not [[verdict-from-probe-competence]] in disguise.

⭐⭐ The general form, and the reason this ranks with [[verify-the-subject-not-just-the-measurement]]: **a shared
filename is not a shared file.** It landed on the two people who pressed the artifact-vs-claim rule hardest all
night, about the very file whose job was to record that night's lessons.

⭐⭐ **NEW FACE (2026-08-23, field-acceptance window): A COMMUNE CAN TESTIFY TO AN ACTION, NOT JUST
AN ARTIFACT — "question sent ~04:30" described a send that NEVER HAPPENED.** My pre-clear commune
claimed the roll-3 shape question was sent to doyle; the transcript (one jsonl spans a self-clear,
so the window is fully auditable) shows ZERO outbound of any kind between doyle's 04:20:54 ruling
and the 04:22:51 clear — the clear cut off the intended send. Post-clear me then REPEATED the
false claim in a "reminder" instead of verifying it, and doyle spent a forensic pass hunting a
delivery loss that never occurred (it nearly got attributed to perri's real tag seam — a false
row in someone else's defect ledger).
- **After any self-clear, verify the final turn's claimed OUTBOUNDS against the transcript**
  (grep the session jsonl for `spt send <peer>` tool_uses and `@<peer` text tags, with
  timestamps) before repeating them. Verbs need the same stat-before-cite discipline as paths.
- **Commune the send AFTER the tool result, never before** — "sending X next" is a plan; only
  `SENT`/`QUEUED` in a result is a send.
- Sibling fact measured in the same audit, for anyone auditing deliveries: **a SENT (live)
  delivery writes NO spool row on the receiver** — doyle's spool audit called my received-and-
  answered report1 "no row"; spool rows are QUEUED arrivals only. An audit population that
  excludes live deliveries reads every successful live send as a loss
  ([[verdict-from-probe-competence]] wearing a spool).

Related: [[precise-claim-is-falsifiable-vague-is-useless]], [[absence-needs-sibling-probe]],
[[milestone-a-golden-landed]].

## [root-merge 2026-08-23] lines present only in the .ccs(bigscreen) copy (union-merged at alt-profile migration; placement lost, content verbatim)

⭐⭐ **THE FACE WITH NOTHING TO STAT: A COMMUNE CLAIMING YOU SENT SOMETHING.** 2026-08-04, mine. My
commune read *"ESCALATION he surfaced and I routed to doyle rather than directing … doyle has not
ruled on it yet"* — and my wake message repeated it as an open item. **doyle: "I have NO such item
in hand — nothing from deployah names a runbook escalation awaiting my ruling."** deployah
independently confirmed the gap was mine→doyle: he had explicitly declined to route it himself
because I undertook to report it as DRI with his numbers attributed.
- **Every remedy above assumes an artifact you can `stat`. A claimed OUTBOUND ACT has none.** No
  file, no branch, no sha — the sender's transcript was the only record and the clear took it.
  Unfalsifiable from my side *by construction*; [[delivery-confirmation-is-a-claim-too]] already
  says only the receiver can close a delivery, and a clear removes even the sender's half.
- **The blast radius is a peer's docket.** An artifact claim misleads only me; a routing claim
  parks a phantom pending item on someone ELSE, and I then cite it back at them as "awaiting your
  ruling" — which is how doyle came to be chasing a message that may never have existed.
- **How to apply — do not try to prove the send. Re-derive the CONTENT and re-deliver it.** I could
  not produce a message id, so I said so plainly ("treat my earlier *I routed it* as unverified"),
  then rebuilt the escalation from primary sources in one turn and sent that. Cheaper than
  forensics on a delivery, and it discharges the item either way.
- **Weak positive signal, worth noting, not worth trusting:** the re-send returned `SENT` (live
  perch) where a lost original would more likely have been `QUEUED`. Suggestive that the first send
  never fired; **not** proof — do not upgrade it.
- **When communing, write outbound claims with their evidence or not at all:** "sent X to Y" is
  worthless post-clear; "sent X to Y, `SENT:doyle`" is at least a quoted return, and the durable
  form is to leave the BODY in a tracked file the next you can re-send. I now stage send bodies as
  files ([[send-body-from-file-not-inline]]) — that also makes them survivable.
[[milestone-a-golden-landed]], [[delivery-confirmation-is-a-claim-too]],
[[relay-is-not-the-gaters-word]].
